Back to directory
WRITEUP #2016

From Self-Hosted GitHub Runner to Self-Hosted Backdoor

OtherCI/CDLateral movementPost-exploitation
by@adnanthekhan(Adnan Khan)
Program
GitHub
Published
Oct 26, 2022
Added to HackDex
Feb 6, 2024
Read Full Writeuphttps://www.praetorian.com/blog/self-hosted-github-runners-are-backdoors/
RELATED WRITEUPS
Github Actions Exploitation: Dependabot
OtherCI/CD
Injecting Java In-memory Payloads For Post-exploitation
OtherPost-exploitation
GitHub Actions Exploitation: Self Hosted Runners
OtherCI/CD
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass

Built with ❤️ by Shubham Rawat